US11816672B1ActiveUtility

Flexible authentication

Assignee: WELLS FARGO BANK NAPriority: Sep 22, 2015Filed: Jan 29, 2016Granted: Nov 14, 2023
Est. expirySep 22, 2035(~9.2 yrs left)· nominal 20-yr term from priority
G06Q 2220/00G06Q 20/405G06Q 20/382G06Q 20/40145H04L 63/08H04L 63/0807H04L 63/0861H04L 63/20H04L 2463/082G06Q 20/4016H04L 63/105
89
PatentIndex Score
9
Cited by
53
References
14
Claims

Abstract

Provided is dynamic and flexible authentication based on an interaction over a communications link between a user device and a financial entity. A set of interactions enabled at the user device are categorized into different levels, each level comprises a different authentication policy. At about the same time as an interaction is initiated at the device, an authentication policy assigned to the interaction is accessed and a security challenge is activated at the device. Based upon a successful response to the security challenge, an enablement of the communications link is continued. Based upon an unsuccessful response to the security challenge, the communications link is disabled.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 categorizing, by a system comprising a processor, a set of financial interactions into different levels of authentication;   designating, by the system, an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy;   evaluating, by the system, an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes: 
 assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device, 
 assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and 
 assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction; 
   as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to beperformed by the user of the device;   receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed;   authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and   approving, by the system, performance of the interaction at the device based on authenticating the user.   
     
     
         2 . The method of  claim 1 , wherein approving performance of the interaction comprises continuing the enablement of the communications link between the device and the financial entity as a function of an expected response to the security challenge. 
     
     
         3 . The method of  claim 1 , wherein not approving performance of the interaction comprises disabling the communications link between the device and the financial entity based on an unexpected response to the security challenge. 
     
     
         4 . The method of  claim 1 , wherein assigning a confidence level to the interaction further comprises:
 determining a location where initiation of the interaction occurs; and   evaluating historical information associated with the location.   
     
     
         5 . The method of  claim 1 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user. 
     
     
         6 . A non-transitory computer-readable storage device storing executable instructions that, in response to execution, cause a system comprising a processor to perform operations, the operations comprising:
 categorizing a set of financial interactions into different levels of authentication;   designating an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy;   evaluating an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes: 
 assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device, 
 assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and 
 assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction; 
   as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to be performed by the user of the device;   receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed;   authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and   approving performance of the interaction at the device based on authenticating the user.   
     
     
         7 . The computer-readable storage device of  claim 6 , wherein the operations further comprise requesting a third party token or a biometric identification as at least a portion of the security challenge. 
     
     
         8 . The computer-readable storage device of  claim 6 , wherein the operations further comprise requesting a third party token and a biometric identification as at least a portion of the security challenge. 
     
     
         9 . The computer-readable storage device of  claim 6 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user. 
     
     
         10 . A system, comprising:
 a memory that stores executable code and a processor configured to execute the executable code, and upon execution causes: 
 categorizing a set of financial interactions into different levels of authentication; 
 designating an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy; 
 evaluating an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes: 
 assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device, 
 assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and 
 assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction; 
 
   as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to be performed by the user of the device;   receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed;   authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and   approving performance of the interaction at the device based on authenticating the user.   
     
     
         11 . The system of  claim 10 , wherein approving performance of the interaction comprises continuing the enablement of the communications link between the device and the financial entity as a function of an expected response to the security challenge. 
     
     
         12 . The system of  claim 10 , wherein not approving performance of the interaction comprises disabling the communications link between the device and the financial entity based on an unexpected response to the security challenge. 
     
     
         13 . The system of  claim 10 , wherein assigning a confidence level to the interaction further comprises:
 determining a location where initiation of the interaction occurs; and   evaluating historical information associated with the location.   
     
     
         14 . The system of  claim 10 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user.

Join the waitlist — get patent alerts

Track US11816672B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.